[CLSA-2026:1787822902] Fix CVE(s): CVE-2025-13643, CVE-2026-9740, CVE-2026-9750, CVE-2026-9751
Type:
security
Severity:
Important
Release date:
2026-08-27 09:28:34 UTC
Description:
* SECURITY UPDATE: Authorization bypass through collisions between user fields and system metadata - debian/patches/CVE-2026-9750.patch: keep user-supplied metadata field names separate from system-injected document metadata - CVE-2026-9750 * SECURITY UPDATE: Denial of service through nested BSONColumn values - debian/patches/CVE-2026-9740.patch: reject BSONColumn values nested in literal or interleaved BSONColumn content - CVE-2026-9740 * SECURITY UPDATE: Sensitive server parameter values exposed in logs - debian/patches/CVE-2026-9751.patch: force redaction of parameters marked sensitive in setParameter log messages - CVE-2026-9751 * SECURITY UPDATE: Authorization bypass through a race in killCursors - debian/patches/CVE-2025-13643.patch: recheck cursor ownership while holding the cursor manager lock before killing a cursor - CVE-2025-13643
Updated packages:
  • mongodb6_6.0.26-1+tuxcare.els18_amd64.deb
    sha:bbf464e064b50a7e5fa58cb7c061cb7a7f6095b0
  • mongodb6-mongos_6.0.26-1+tuxcare.els18_amd64.deb
    sha:a736544b873982df96ece8af4a17b5cb7e83c797
  • mongodb6-server_6.0.26-1+tuxcare.els18_amd64.deb
    sha:f96c98237d414bf5929e205adc776cee55e576a7
  • mongodb6-shell_6.0.26-1+tuxcare.els18_amd64.deb
    sha:c159e9c2f22c95b6798c8383a05ed1abae83a696
  • mongodb6_6.0.26-1+tuxcare.els18_arm64.deb
    sha:3d07f7d5d068f33a713b7dfa9762d4a295174520
  • mongodb6-mongos_6.0.26-1+tuxcare.els18_arm64.deb
    sha:3504061b4365c7702b17a219759286ccd323a473
  • mongodb6-server_6.0.26-1+tuxcare.els18_arm64.deb
    sha:8d555f069adf34691aac0a87d86de145abace2d4
  • mongodb6-shell_6.0.26-1+tuxcare.els18_arm64.deb
    sha:9cf572e384428fe634c7195c8074ed79d1ce7d99
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.